A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identities who entered and exited the room on what date and at what time There are no video cameras located in the server room Based on this information, which statement is true regarding PCI DSS physical security requirements?
In the ROC Repotting Template, which of the following is the best approach for a response where the requirement was in Place’’?
What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?
An organization has implemented a change-detection mechanism on their systems. How often must critical file comparisons be performed?
Which of the following is required to be included in an incident response plan?
What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128-bit data-encrypting key (DEK)
An LDAP server providing authentication services to the cardholder data environment is
In accordance with PCI DSS Requirement 10. how long must audit logs be retained?
Which of the following file types must be monitored by a change-detection mechanism (for example, a file-integrity monitoring tool)?
Which scenario meets PCI DSS requirements for critical systems to have correct and consistent time?
Which of the following statements is true regarding track equivalent data on the chip of a payment card?